SUSE-SU-2023:1803-1: important: Security update for the Linux Kernel

sle-security-updates at lists.suse.com sle-security-updates at lists.suse.com
Mon Apr 10 12:30:55 UTC 2023



# Security update for the Linux Kernel

Announcement ID: SUSE-SU-2023:1803-1  
Rating: important  
References:

  * #1065729
  * #1076830
  * #1109158
  * #1181001
  * #1191924
  * #1193231
  * #1199837
  * #1203092
  * #1203693
  * #1206010
  * #1207001
  * #1207036
  * #1207125
  * #1207795
  * #1207890
  * #1208048
  * #1208179
  * #1208599
  * #1208777
  * #1208850
  * #1209008
  * #1209052
  * #1209118
  * #1209126
  * #1209256
  * #1209289
  * #1209291
  * #1209292
  * #1209532
  * #1209547
  * #1209549
  * #1209556
  * #1209572
  * #1209634
  * #1209684
  * #1209778
  * #1209798

  
Cross-References:

  * CVE-2017-5753
  * CVE-2021-3923
  * CVE-2022-20567
  * CVE-2023-0590
  * CVE-2023-1076
  * CVE-2023-1095
  * CVE-2023-1281
  * CVE-2023-1390
  * CVE-2023-1513
  * CVE-2023-23454
  * CVE-2023-23455
  * CVE-2023-28328
  * CVE-2023-28464
  * CVE-2023-28772

  
CVSS scores:

  * CVE-2017-5753 ( SUSE ):  7.1 CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
  * CVE-2017-5753 ( NVD ):  5.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
  * CVE-2017-5753 ( NVD ):  5.6 CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
  * CVE-2021-3923 ( SUSE ):  3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
  * CVE-2021-3923 ( NVD ):  2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
  * CVE-2022-20567 ( SUSE ):  6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
  * CVE-2022-20567 ( NVD ):  6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
  * CVE-2023-0590 ( SUSE ):  7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2023-0590 ( NVD ):  4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
  * CVE-2023-1076 ( SUSE ):  4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
  * CVE-2023-1076 ( NVD ):  5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
  * CVE-2023-1095 ( SUSE ):  5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2023-1095 ( NVD ):  5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  * CVE-2023-1281 ( SUSE ):  7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2023-1281 ( NVD ):  7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2023-1390 ( SUSE ):  6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  * CVE-2023-1390 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2023-1513 ( SUSE ):  3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
  * CVE-2023-1513 ( NVD ):  3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
  * CVE-2023-23454 ( SUSE ):  7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2023-23454 ( NVD ):  5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  * CVE-2023-23455 ( SUSE ):  7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2023-23455 ( NVD ):  5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  * CVE-2023-28464 ( SUSE ):  4.8 CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
  * CVE-2023-28464 ( NVD ):  7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2023-28772 ( SUSE ):  3.0 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L
  * CVE-2023-28772 ( NVD ):  7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

  
Affected Products:

  * SUSE Linux Enterprise High Availability Extension 12 SP5
  * SUSE Linux Enterprise High Performance Computing 12 SP5
  * SUSE Linux Enterprise Live Patching 12-SP5
  * SUSE Linux Enterprise Server 12 SP5
  * SUSE Linux Enterprise Server for SAP Applications 12 SP5
  * SUSE Linux Enterprise Software Development Kit 12 SP5
  * SUSE Linux Enterprise Workstation Extension 12 12-SP5

  
  
An update that solves 14 vulnerabilities, contains one feature and has 23 fixes
can now be installed.

## Description:

The SUSE Linux Enterprise 12 SP5 kernel was updated to receive various security
and bugfixes.

The following security bugs were fixed:

  * CVE-2017-5753: Fixed spectre V1 vulnerability on netlink (bsc#1209547).
  * CVE-2017-5753: Fixed spectre vulnerability in prlimit (bsc#1209256).
  * CVE-2021-3923: Fixed stack information leak vulnerability that could lead to
    kernel protection bypass in infiniband RDMA (bsc#1209778).
  * CVE-2022-20567: Fixed use after free that could lead to a local privilege
    escalation in pppol2tp_create of l2tp_ppp.c (bsc#1208850).
  * CVE-2023-0590: Fixed race condition in qdisc_graft() (bsc#1207795).
  * CVE-2023-1076: Fixed incorrect UID assigned to tun/tap sockets
    (bsc#1208599).
  * CVE-2023-1095: Fixed a NULL pointer dereference in nf_tables due to zeroed
    list head (bsc#1208777).
  * CVE-2023-1281: Fixed use after free that could lead to privilege escalation
    in tcindex (bsc#1209634).
  * CVE-2023-1390: Fixed remote DoS vulnerability in tipc_link_xmit()
    (bsc#1209289).
  * CVE-2023-1513: Fixed an uninitialized portions of the kvm_debugregs
    structure that could be copied to userspace, causing an information leak
    (bsc#1209532).
  * CVE-2023-23454: Fixed a type-confusion in the CBQ network scheduler
    (bsc#1207036).
  * CVE-2023-23455: Fixed a denial of service inside atm_tc_enqueue in
    net/sched/sch_atm.c because of type confusion (non-negative numbers can
    sometimes indicate a TC_ACT_SHOT condition rather than valid classification
    results) (bsc#1207125).
  * CVE-2023-28328: Fixed a denial of service issue in az6027 driver in
    drivers/media/usb/dev-usb/az6027.c (bsc#1209291).
  * CVE-2023-28464: Fixed user-after-free that could lead to privilege
    escalation in hci_conn_cleanup in net/bluetooth/hci_conn.c (bsc#1209052).
  * CVE-2023-28772: Fixed buffer overflow in seq_buf_putmem_hex in lib/seq_buf.c
    (bsc#1209549).

The following non-security bugs were fixed:

  * Bluetooth: btusb: Add VID:PID 13d3:3529 for Realtek RTL8821CE (git-fixes).
  * Bluetooth: btusb: do not call kfree_skb() under spin_lock_irqsave() (git-
    fixes).
  * Do not sign the vanilla kernel (bsc#1209008).
  * Input: atmel_mxt_ts - fix double free in mxt_read_info_block (git-fixes).
  * KVM: arm64: Hide system instruction access to Trace registers (git-fixes)
  * NFSv4: Fix hangs when recovering open state after a server reboot (git-
    fixes). [iivanov] Fix Patch-mainline to v6.3-rc5
  * PCI/MSI: Enforce MSI entry updates to be visible (git-fixes).
  * PCI/MSI: Enforce that MSI-X table entry is masked for update (git-fixes).
  * PCI/MSI: Mask all unused MSI-X entries (git-fixes).
  * PCI/MSI: Skip masking MSI-X on Xen PV (git-fixes).
  * PCI/PM: Always return devices to D0 when thawing (git-fixes).
  * PCI/PM: Avoid using device_may_wakeup() for runtime PM (git-fixes).
  * PCI: Add ACS quirk for Intel Root Complex Integrated Endpoints (git-fixes).
  * PCI: Add ACS quirk for iProc PAXB (git-fixes).
  * PCI: Avoid FLR for AMD Matisse HD Audio & USB 3.0 (git-fixes).
  * PCI: Avoid FLR for AMD Starship USB 3.0 (git-fixes).
  * PCI: Make ACS quirk implementations more uniform (git-fixes).
  * PCI: PM: Avoid forcing PCI_D0 for wakeup reasons inconsistently (git-fixes).
  * PCI: PM: Avoid skipping bus-level PM on platforms without ACPI (git-fixes).
  * PCI: Unify ACS quirk desired vs provided checking (git-fixes).
  * PCI: Use pci_update_current_state() in pci_enable_device_flags() (git-
    fixes).
  * PCI: aardvark: Do not blindly enable ASPM L0s and do not write to read-only
    register (git-fixes).
  * PCI: aardvark: Do not rely on jiffies while holding spinlock (git-fixes).
  * PCI: aardvark: Do not touch PCIe registers if no card connected (git-fixes).
  * PCI: aardvark: Fix a leaked reference by adding missing of_node_put() (git-
    fixes).
  * PCI: aardvark: Fix checking for PIO Non-posted Request (git-fixes).
  * PCI: aardvark: Fix kernel panic during PIO transfer (git-fixes).
  * PCI: aardvark: Improve link training (git-fixes).
  * PCI: aardvark: Indicate error in 'val' when config read fails (git-fixes).
  * PCI: aardvark: Introduce an advk_pcie_valid_device() helper (git-fixes).
  * PCI: aardvark: Remove PCIe outbound window configuration (git-fixes).
  * PCI: aardvark: Train link immediately after enabling training (git-fixes).
  * PCI: aardvark: Wait for endpoint to be ready before training link (git-
    fixes).
  * PCI: endpoint: Cast the page number to phys_addr_t (git-fixes).
  * PCI: endpoint: Fix for concurrent memory allocation in OB address region
    (git-fixes).
  * PCI: hv: Add a per-bus mutex state_lock (bsc#1207001).
  * PCI: hv: Fix a race condition in hv_irq_unmask() that can cause panic
    (bsc#1207001).
  * PCI: hv: Remove the useless hv_pcichild_state from struct hv_pci_dev
    (bsc#1207001).
  * PCI: hv: fix a race condition bug in hv_pci_query_relations() (bsc#1207001).
  * PCI: qcom: Use PHY_REFCLK_USE_PAD only for ipq8064 (git-fixes).
  * PCI: tegra: Fix OF node reference leak (git-fixes).
  * PCI: xgene-msi: Fix race in installing chained irq handler (git-fixes).
  * PM: hibernate: flush swap writer after marking (git-fixes).
  * README.BRANCH: Adding myself to the maintainer list
  * README: remove copy of config and update the text (bsc#1191924)
  * Revert "PCI: hv: Fix a timing issue which causes kdump to fail occasionally"
    (bsc#1207001).
  * Revert "arm64: dts: juno: add dma-ranges property" (git-fixes)
  * Revert "mei: me: enable asynchronous probing" (bsc#1208048, bsc#1209126).
  * SUNRPC: Fix a server shutdown leak (git-fixes).
  * applicom: Fix PCI device refcount leak in applicom_init() (git-fixes).
  * arm64/alternatives: do not patch up internal branches (git-fixes)
  * arm64/alternatives: move length validation inside the subsection (git-fixes)
  * arm64/alternatives: use subsections for replacement sequences (git-fixes)
  * arm64/cpufeature: Fix field sign for DIT hwcap detection (git-fixes)
  * arm64/mm: fix variable 'pud' set but not used (git-fixes)
  * arm64/mm: return cpu_all_mask when node is NUMA_NO_NODE (git-fixes)
  * arm64/vdso: Discard .note.gnu.property sections in vDSO (git-fixes)
  * arm64: Discard .note.GNU-stack section (bsc#1203693 bsc#1209798).
  * arm64: Do not forget syscall when starting a new thread. (git-fixes)
  * arm64: Fix compiler warning from pte_unmap() with (git-fixes)
  * arm64: Mark __stack_chk_guard as __ro_after_init (git-fixes)
  * arm64: Use test_tsk_thread_flag() for checking TIF_SINGLESTEP (git-fixes)
  * arm64: cmpxchg_double*: hazard against entire exchange variable (git-fixes)
  * arm64: cpu_ops: fix a leaked reference by adding missing of_node_put (git-
    fixes)
  * arm64: fix oops in concurrently setting insn_emulation sysctls (git-fixes)
  * arm64: kprobe: make page to RO mode when allocate it (git-fixes)
  * arm64: kpti: ensure patched kernel text is fetched from PoU (git-fixes)
  * arm64: psci: Avoid printing in cpu_psci_cpu_die() (git-fixes)
  * arm64: psci: Reduce the waiting time for cpu_psci_cpu_kill() (git-fixes)
  * arm64: unwind: Prohibit probing on return_address() (git-fixes)
  * crypto: arm64 - Fix unused variable compilation warnings of (git-fixes)
  * dt-bindings: reset: meson8b: fix duplicate reset IDs (git-fixes).
  * ftrace: Fix invalid address access in lookup_rec() when index is 0 (git-
    fixes).
  * git_sort: tests: Adjust to new net repository location
  * git_sort: tests: Fix tests failing on SLE15 Use the correct base image,
    pygit2 is not found by pythong otherwise.
  * git_sort: tests: Kernel:tools does not have Leap repos, use SLE
  * git_sort: tests: Use 15.4, 15.3 is EOL
  * git_sort: tests: do not disable package repository GPG check This adds the
    Kernel repository key and enables GPG check for package installation inside
    containers.
  * git_sort: tests: exit on error
  * ima: Fix function name error in comment (git-fixes).
  * ipv4: route: fix inet_rtm_getroute induced crash (git-fixes).
  * kabi: PCI: endpoint: Fix for concurrent memory allocation in OB address
    region (git-fixes).
  * kernel-module-subpackage: Fix expansion with -b parameter (bsc#1208179).
  * kfifo: fix ternary sign extension bugs (git-fixes).
  * kgdb: Drop malformed kernel doc comment (git-fixes).
  * media: coda: Add check for dcoda_iram_alloc (git-fixes).
  * media: coda: Add check for kmalloc (git-fixes).
  * media: platform: ti: Add missing check for devm_regulator_get (git-fixes).
  * net: usb: lan78xx: Limit packet length to skb->len (git-fixes).
  * net: usb: qmi_wwan: Adding support for Cinterion MV31 (git-fixes).
  * net: usb: smsc75xx: Limit packet length to skb->len (git-fixes).
  * net: usb: smsc75xx: Move packet length check to prevent kernel panic in
    skb_pull (git-fixes).
  * net: usb: smsc95xx: Limit packet length to skb->len (git-fixes).
  * powerpc/btext: add missing of_node_put (bsc#1065729).
  * powerpc/powernv/ioda: Skip unallocated resources when mapping to PE
    (bsc#1065729).
  * powerpc/pseries/lpar: add missing RTAS retry status handling (bsc#1109158
    ltc#169177 git-fixes).
  * powerpc/pseries/lparcfg: add missing RTAS retry status handling
    (bsc#1065729).
  * powerpc/rtas: ensure 4KB alignment for rtas_data_buf (bsc#1065729).
  * powerpc/xics: fix refcount leak in icp_opal_init() (bsc#1065729).
  * ppc64le: HWPOISON_INJECT=m (bsc#1209572).
  * ring-buffer: remove obsolete comment for free_buffer_page() (git-fixes).
  * s390/vfio-ap: fix memory leak in vfio_ap device driver (git-fixes).
  * sbitmap: Avoid lockups when waker gets preempted (bsc#1209118).
  * scripts/osc_wrapper: Assign spec with *.spec file when building.
  * scripts/sequence-patch.sh: remove obsolete egrep Avoids a warning and
    prepares for ultimate removal - boo#1203092
  * scsi: lpfc: Return DID_TRANSPORT_DISRUPTED instead of DID_REQUEUE
    (bsc#1199837).
  * scsi: qla2xxx: Synchronize the IOCB count to be in order (bsc#1209292
    bsc#1209684 bsc#1209556).
  * timers/sched_clock: Prevent generic sched_clock wrap caused by tick_freeze()
    (git-fixes).
  * timers: Clear timer_base::must_forward_clk with (bsc#1207890)
  * tracing/hwlat: Replace sched_setaffinity with set_cpus_allowed_ptr (git-
    fixes).
  * tracing: Add NULL checks for buffer in ring_buffer_free_read_page() (git-
    fixes).
  * usb: chipidea: fix deadlock in ci_otg_del_timer (git-fixes).
  * usb: dwc3: exynos: Fix remove() function (git-fixes).
  * usb: dwc3: gadget: Stop processing more requests on IMI (git-fixes).
  * usb: misc: iowarrior: fix up header size for USB_DEVICE_ID_CODEMERCS_IOW100
    (git-fixes).
  * usb: typec: altmodes/displayport: Fix probe pin assign check (git-fixes).
  * x86/PCI: Fix PCI IRQ routing table memory leak (git-fixes).
  * x86/apic: Add name to irq chip (bsc#1206010).
  * x86/apic: Deinline x2apic functions (bsc#1181001 jsc#ECO-3191).
  * x86/atomic: Fix smp_mb__{before,after}_atomic() (git-fixes).
  * x86/build: Add 'set -e' to mkcapflags.sh to delete broken capflags.c (git-
    fixes).
  * x86/ia32: Fix ia32_restore_sigcontext() AC leak (git-fixes).
  * x86/ioapic: Force affinity setup before startup (bsc#1193231).
  * x86/irq/64: Limit IST stack overflow check to #DB stack (git-fixes).
  * x86/mm: Remove in_nmi() warning from 64-bit implementation of
    vmalloc_fault() (git-fixes).
  * x86/paravirt: Fix callee-saved function ELF sizes (git-fixes).
  * x86/power: Fix 'nosmt' vs hibernation triple fault during resume (git-
    fixes).
  * x86/stacktrace: Prevent infinite loop in arch_stack_walk_user() (git-fixes).
  * x86/uaccess, signal: Fix AC=1 bloat (git-fixes).
  * x86/x2apic: Mark set_x2apic_phys_mode() as __init (bsc#1181001
    jsc#ECO-3191).
  * x86/xen: Fix memory leak in xen_init_lock_cpu() (git-fixes).
  * x86/xen: Fix memory leak in xen_smp_intr_init{_pv}() (git-fixes).
  * xen-netfront: Fix NULL sring after live migration (git-fixes).
  * xen-netfront: Fix mismatched rtnl_unlock (git-fixes).
  * xen-netfront: Fix race between device setup and open (git-fixes).
  * xen-netfront: Update features after registering netdev (git-fixes).
  * xen-netfront: enable device after manual module load (git-fixes).
  * xen-netfront: fix potential deadlock in xennet_remove() (git-fixes).
  * xen-netfront: wait xenbus state change when load module manually (git-
    fixes).
  * xen/netfront: fix waiting for xenbus state change (git-fixes).
  * xen/netfront: stop tx queues during live migration (git-fixes).
  * xen/platform-pci: add missing free_irq() in error path (git-fixes).

## Special Instructions and Notes:

  * Please reboot the system after installing this update.

## Patch Instructions:

To install this SUSE Important update use the SUSE recommended installation
methods like YaST online_update or "zypper patch".  
Alternatively you can run the command listed for your product:

  * SUSE Linux Enterprise Server for SAP Applications 12 SP5  
    zypper in -t patch SUSE-SLE-HA-12-SP5-2023-1803=1 SUSE-SLE-
SERVER-12-SP5-2023-1803=1

  * SUSE Linux Enterprise High Availability Extension 12 SP5  
    zypper in -t patch SUSE-SLE-HA-12-SP5-2023-1803=1

  * SUSE Linux Enterprise Live Patching 12-SP5  
    zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2023-1803=1

  * SUSE Linux Enterprise Software Development Kit 12 SP5  
    zypper in -t patch SUSE-SLE-SDK-12-SP5-2023-1803=1

  * SUSE Linux Enterprise High Performance Computing 12 SP5  
    zypper in -t patch SUSE-SLE-SERVER-12-SP5-2023-1803=1

  * SUSE Linux Enterprise Server 12 SP5  
    zypper in -t patch SUSE-SLE-SERVER-12-SP5-2023-1803=1

  * SUSE Linux Enterprise Workstation Extension 12 12-SP5  
    zypper in -t patch SUSE-SLE-WE-12-SP5-2023-1803=1

## Package List:

  * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (ppc64le x86_64)
    * kernel-default-devel-4.12.14-122.156.1
    * kernel-syms-4.12.14-122.156.1
    * kernel-default-debuginfo-4.12.14-122.156.1
    * ocfs2-kmp-default-4.12.14-122.156.1
    * kernel-default-debugsource-4.12.14-122.156.1
    * cluster-md-kmp-default-debuginfo-4.12.14-122.156.1
    * dlm-kmp-default-debuginfo-4.12.14-122.156.1
    * ocfs2-kmp-default-debuginfo-4.12.14-122.156.1
    * kernel-default-base-debuginfo-4.12.14-122.156.1
    * gfs2-kmp-default-4.12.14-122.156.1
    * cluster-md-kmp-default-4.12.14-122.156.1
    * dlm-kmp-default-4.12.14-122.156.1
    * gfs2-kmp-default-debuginfo-4.12.14-122.156.1
    * kernel-default-base-4.12.14-122.156.1
  * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (nosrc ppc64le
    x86_64)
    * kernel-default-4.12.14-122.156.1
  * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (noarch)
    * kernel-devel-4.12.14-122.156.1
    * kernel-macros-4.12.14-122.156.1
    * kernel-source-4.12.14-122.156.1
  * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (x86_64)
    * kernel-default-devel-debuginfo-4.12.14-122.156.1
  * SUSE Linux Enterprise High Availability Extension 12 SP5 (ppc64le s390x
    x86_64)
    * kernel-default-debuginfo-4.12.14-122.156.1
    * ocfs2-kmp-default-4.12.14-122.156.1
    * kernel-default-debugsource-4.12.14-122.156.1
    * cluster-md-kmp-default-debuginfo-4.12.14-122.156.1
    * dlm-kmp-default-debuginfo-4.12.14-122.156.1
    * ocfs2-kmp-default-debuginfo-4.12.14-122.156.1
    * gfs2-kmp-default-4.12.14-122.156.1
    * cluster-md-kmp-default-4.12.14-122.156.1
    * dlm-kmp-default-4.12.14-122.156.1
    * gfs2-kmp-default-debuginfo-4.12.14-122.156.1
  * SUSE Linux Enterprise High Availability Extension 12 SP5 (nosrc)
    * kernel-default-4.12.14-122.156.1
  * SUSE Linux Enterprise Live Patching 12-SP5 (nosrc)
    * kernel-default-4.12.14-122.156.1
  * SUSE Linux Enterprise Live Patching 12-SP5 (ppc64le s390x x86_64)
    * kernel-default-kgraft-4.12.14-122.156.1
    * kernel-default-debuginfo-4.12.14-122.156.1
    * kernel-default-debugsource-4.12.14-122.156.1
    * kernel-default-kgraft-devel-4.12.14-122.156.1
    * kgraft-patch-4_12_14-122_156-default-1-8.3.1
  * SUSE Linux Enterprise Software Development Kit 12 SP5 (noarch nosrc)
    * kernel-docs-4.12.14-122.156.1
  * SUSE Linux Enterprise Software Development Kit 12 SP5 (aarch64 ppc64le s390x
    x86_64)
    * kernel-obs-build-4.12.14-122.156.1
    * kernel-obs-build-debugsource-4.12.14-122.156.1
  * SUSE Linux Enterprise High Performance Computing 12 SP5 (aarch64 nosrc
    x86_64)
    * kernel-default-4.12.14-122.156.1
  * SUSE Linux Enterprise High Performance Computing 12 SP5 (aarch64 x86_64)
    * kernel-default-devel-4.12.14-122.156.1
    * kernel-syms-4.12.14-122.156.1
    * kernel-default-debuginfo-4.12.14-122.156.1
    * kernel-default-debugsource-4.12.14-122.156.1
    * kernel-default-base-debuginfo-4.12.14-122.156.1
    * kernel-default-base-4.12.14-122.156.1
  * SUSE Linux Enterprise High Performance Computing 12 SP5 (noarch)
    * kernel-devel-4.12.14-122.156.1
    * kernel-macros-4.12.14-122.156.1
    * kernel-source-4.12.14-122.156.1
  * SUSE Linux Enterprise High Performance Computing 12 SP5 (x86_64)
    * kernel-default-devel-debuginfo-4.12.14-122.156.1
  * SUSE Linux Enterprise Server 12 SP5 (aarch64 ppc64le s390x x86_64 nosrc)
    * kernel-default-4.12.14-122.156.1
  * SUSE Linux Enterprise Server 12 SP5 (aarch64 ppc64le s390x x86_64)
    * kernel-default-devel-4.12.14-122.156.1
    * kernel-syms-4.12.14-122.156.1
    * kernel-default-debuginfo-4.12.14-122.156.1
    * kernel-default-debugsource-4.12.14-122.156.1
    * kernel-default-base-debuginfo-4.12.14-122.156.1
    * kernel-default-base-4.12.14-122.156.1
  * SUSE Linux Enterprise Server 12 SP5 (noarch)
    * kernel-devel-4.12.14-122.156.1
    * kernel-macros-4.12.14-122.156.1
    * kernel-source-4.12.14-122.156.1
  * SUSE Linux Enterprise Server 12 SP5 (s390x)
    * kernel-default-man-4.12.14-122.156.1
  * SUSE Linux Enterprise Server 12 SP5 (x86_64)
    * kernel-default-devel-debuginfo-4.12.14-122.156.1
  * SUSE Linux Enterprise Workstation Extension 12 12-SP5 (nosrc)
    * kernel-default-4.12.14-122.156.1
  * SUSE Linux Enterprise Workstation Extension 12 12-SP5 (x86_64)
    * kernel-default-debugsource-4.12.14-122.156.1
    * kernel-default-extra-debuginfo-4.12.14-122.156.1
    * kernel-default-debuginfo-4.12.14-122.156.1
    * kernel-default-extra-4.12.14-122.156.1

## References:

  * https://www.suse.com/security/cve/CVE-2017-5753.html
  * https://www.suse.com/security/cve/CVE-2021-3923.html
  * https://www.suse.com/security/cve/CVE-2022-20567.html
  * https://www.suse.com/security/cve/CVE-2023-0590.html
  * https://www.suse.com/security/cve/CVE-2023-1076.html
  * https://www.suse.com/security/cve/CVE-2023-1095.html
  * https://www.suse.com/security/cve/CVE-2023-1281.html
  * https://www.suse.com/security/cve/CVE-2023-1390.html
  * https://www.suse.com/security/cve/CVE-2023-1513.html
  * https://www.suse.com/security/cve/CVE-2023-23454.html
  * https://www.suse.com/security/cve/CVE-2023-23455.html
  * https://www.suse.com/security/cve/CVE-2023-28328.html
  * https://www.suse.com/security/cve/CVE-2023-28464.html
  * https://www.suse.com/security/cve/CVE-2023-28772.html
  * https://bugzilla.suse.com/show_bug.cgi?id=1065729
  * https://bugzilla.suse.com/show_bug.cgi?id=1076830
  * https://bugzilla.suse.com/show_bug.cgi?id=1109158
  * https://bugzilla.suse.com/show_bug.cgi?id=1181001
  * https://bugzilla.suse.com/show_bug.cgi?id=1191924
  * https://bugzilla.suse.com/show_bug.cgi?id=1193231
  * https://bugzilla.suse.com/show_bug.cgi?id=1199837
  * https://bugzilla.suse.com/show_bug.cgi?id=1203092
  * https://bugzilla.suse.com/show_bug.cgi?id=1203693
  * https://bugzilla.suse.com/show_bug.cgi?id=1206010
  * https://bugzilla.suse.com/show_bug.cgi?id=1207001
  * https://bugzilla.suse.com/show_bug.cgi?id=1207036
  * https://bugzilla.suse.com/show_bug.cgi?id=1207125
  * https://bugzilla.suse.com/show_bug.cgi?id=1207795
  * https://bugzilla.suse.com/show_bug.cgi?id=1207890
  * https://bugzilla.suse.com/show_bug.cgi?id=1208048
  * https://bugzilla.suse.com/show_bug.cgi?id=1208179
  * https://bugzilla.suse.com/show_bug.cgi?id=1208599
  * https://bugzilla.suse.com/show_bug.cgi?id=1208777
  * https://bugzilla.suse.com/show_bug.cgi?id=1208850
  * https://bugzilla.suse.com/show_bug.cgi?id=1209008
  * https://bugzilla.suse.com/show_bug.cgi?id=1209052
  * https://bugzilla.suse.com/show_bug.cgi?id=1209118
  * https://bugzilla.suse.com/show_bug.cgi?id=1209126
  * https://bugzilla.suse.com/show_bug.cgi?id=1209256
  * https://bugzilla.suse.com/show_bug.cgi?id=1209289
  * https://bugzilla.suse.com/show_bug.cgi?id=1209291
  * https://bugzilla.suse.com/show_bug.cgi?id=1209292
  * https://bugzilla.suse.com/show_bug.cgi?id=1209532
  * https://bugzilla.suse.com/show_bug.cgi?id=1209547
  * https://bugzilla.suse.com/show_bug.cgi?id=1209549
  * https://bugzilla.suse.com/show_bug.cgi?id=1209556
  * https://bugzilla.suse.com/show_bug.cgi?id=1209572
  * https://bugzilla.suse.com/show_bug.cgi?id=1209634
  * https://bugzilla.suse.com/show_bug.cgi?id=1209684
  * https://bugzilla.suse.com/show_bug.cgi?id=1209778
  * https://bugzilla.suse.com/show_bug.cgi?id=1209798
  * https://jira.suse.com/browse/ECO-3191

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-security-updates/attachments/20230410/65b26ee7/attachment.htm>


More information about the sle-security-updates mailing list